Privacy Policy
IRMP Forest and Forest PINGER9000 are private, personal tools operated for the account owner's own use. This policy explains how the application handles data authorized through Google OAuth.
Google data the application can access
The application requests two Google OAuth permissions:
- Google Drive read-only: to read specifically selected or workflow-bound Drive files and exact revisions needed for a requested Forest review.
- Google Sheets: to read and update the owner's private Forest coordination spreadsheet when a bounded workflow requires it.
How Google data is used
Authorized Google data is used only to perform the owner's requested Forest automation and review workflows. The application does not use Google data for advertising, marketing profiles, credit decisions, or sale to third parties.
AI processing
When a requested review requires language-model processing, the minimum relevant content from an authorized source may be sent to the OpenAI API solely to perform that requested review or automation. OAuth access tokens, refresh tokens, client secrets, and authorization codes are not sent to OpenAI for model processing.
Storage and retention
OAuth credentials are stored locally on the owner's computer in a protected local secrets directory. Workflow records, receipts, and bounded review outputs may be retained locally or in the owner's private Forest repositories or coordination records as needed for continuity, replay protection, auditing, and verification.
Sharing
IRMP Forest does not sell Google user data. Google data is not shared with advertisers or data brokers. Data may be transmitted to service providers only as necessary to operate the requested workflow, including Google APIs and, when required for a review, the OpenAI API.
Cookies, analytics, and tracking
This public information site does not use advertising cookies, analytics trackers, or behavioral profiling scripts.
Security
The application is designed to use least-privilege Google access, local credential storage, bounded workflow rules, explicit replay protection, and fail-closed behavior when required verification cannot be established.
Revoking access
The account owner can revoke the application's Google access at any time through Google Account security settings. Revocation prevents future API access until authorization is granted again.
Google API Services User Data Policy
Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Contact
Questions about this policy can be sent to support@irmp-forest.com.
This policy may be updated when the application's data-access behavior materially changes. The effective date above will be updated accordingly.